[Ncsg-discuss] SCCI Criteria 4 - “domain name security threats”

Johan Helsingius 00001963cc94b85a-dmarc-request at LISTSERV.SYR.EDU
Thu Jun 18 21:07:31 EEST 2026


All,

In light of this clarification from Manju, I would be inclined to
approve the proposed wording change. If any of you disagree
strongly, please speak up.

	Julf


On 18/06/2026 10:16 am, Manju wrote:
> Hi all,
> 
> Thank you for the questions.
> 
> Before answering them, please allow me to provide more context on what 
> we're doing in the SCCI with the Continuous Improvement Program Pilot 
> and what the criteria and indicators are for.
> 
> The Continuous Improvement Program (CIP) is ICANN's evolution of its 
> traditional Organizational Reviews, which previously assessed how well 
> Supporting Organizations, Advisory Committees, and the Nominating 
> Committee fulfilled their purpose, structure, and accountability.
> 
> The CIP rests on five shared principles covering purpose, structural 
> effectiveness, operational efficiency, accountability, and 
> collaboration. Each CIP assessment cycle runs up to three years and 
> moves through three phases:
> 
>   * Assessment and Prioritization (data collection and identifying
>     improvement areas),
>   * Improvements (implementing changes), and
>   * Reporting (publishing results for public comment). 
> 
> As the body in GNSO that's responsible for continuous improvement, SCCI 
> has been following the CIP framework and principles to develop the 
> criteria and indicators for future assessment and improvements. You can 
> find the full set of criteria and indicators here: https:// 
> docs.google.com/document/d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/ 
> edit?tab=t.0#heading=h.49smw22t8kla <https://docs.google.com/document/ 
> d/1UoqrIjNArJFztNZ1Z9htTHCEIhJvIf2PNGLXgE_5HC0/edit? 
> tab=t.0#heading=h.49smw22t8kla>
> 
> *Note: Please refrain from commenting on the Google Doc as we're 
> currently only allowing the SCCI members to comment.*
> *
> *
> In short, we are now developing criteria and indicators for future data 
> collection. And after collecting the data, we will assess it against the 
> indicators and criteria, evaluating whether there is room for improvement.
> 
> What you were asked to review was one of the indicators, and as it is a 
> data point where we will be collecting data to assess against, we in 
> SCCI decided to word it open-ended enough to allow the ease of data 
> collection, while preventing scope creep by adding wording such as 'in 
> scope for GNSO'.
> 
> If you're interested in knowing more, I'd encourage you to listen to the 
> recordings of our ICANN86 session, where we discussed this particular 
> item in depth: https://icann86.sched.com/event/2NQMw/gnso-scci-work- 
> session <https://icann86.sched.com/event/2NQMw/gnso-scci-work-session>
> 
> Hope this helps.
> 
> Best,
> Manju
> 
> On Thu, Jun 18, 2026 at 3:34 PM Tapani Tarvainen <00001e7f5908374c- 
> dmarc-request at listserv.syr.edu <mailto:00001e7f5908374c-dmarc- 
> request at listserv.syr.edu>> wrote:
> 
>     Dear Manju,
> 
>     Thank you for the explanation. Looking at the proposed text again
>     it makes sense. But the language is a bit ambiguous:
> 
>      >      Indicator 1: The GNSO has demonstrated meaningful activity
>     towards
>      >                   mitigating DNS Abuse and security threats
>     relating to
>      >                   domain names that are in scope for the GNSO.
> 
>     Specifically, it's not clear if the qualification "that are in scope..."
>     applies also to DNS Abuse and not only to security threats.
> 
>     I'm not sure this matters here, but perhaps it would be worth
>     thinking a moment if it could be clarified without making the
>     text too cumbersome.
> 
>     Tapani
> 
> 
>     On Jun 17 15:02, Manju (000020eb0920d952-dmarc-
>     request at LISTSERV.SYR.EDU <mailto:000020eb0920d952-dmarc-
>     request at LISTSERV.SYR.EDU>) wrote:
>      >
>      > Hi all,
>      >
>      > Thank you very much for the discussion.
>      > As mentioned by Julf, I'm the chair of SCCI and have to maintain
>     neutrality
>      > when it comes to the discussion of substance. However, I believe I'm
>      > allowed to provide some context and clarification on this issue.
>      >
>      > The change from domain name security threat to DNS Abuse was
>     actually an
>      > effort of the SCCI to tighten the scope, not the contrary. The
>     general
>      > agreement within the SCCI was that "domain name security threat"
>     can be
>      > interpreted to have a broader remit that is beyond GNSO's mission and
>      > scope, which prompted the change to 'DNS Abuse' as narrowly
>     defined in the
>      > contract.
>      >
>      > One of the examples that can be understood as 'combating domain name
>      > security threat', as shared during our SCCI working session in
>     Seville, is
>      > the Internationalized Domain Names PDP, which regulates the variant
>      > management of IDNs. By this example, it should be clear that
>     domain name
>      > security threat actually has a broader scope than DNS abuse, the
>     latter of
>      > which is narrowly defined and codified in contract.
>      >
>      > Hope this helps.
>      >
>      > Best,
>      > Manju
>      >
>      > On Tue, Jun 16, 2026 at 8:36 PM farzaneh badii <
>      > 00001deb507b73c5-dmarc-request at listserv.syr.edu
>     <mailto:00001deb507b73c5-dmarc-request at listserv.syr.edu>> wrote:
>      >
>      > > Hi Julf
>      > >
>      > > I agree and we tried really hard in our public comments to
>     mention the
>      > > security threat and not frame it as DNS abuse, but the CPH and
>     others were
>      > > really keen on adding DNS abuse at the time. Maybe we can
>     clarify that DNS
>      > > abuse as narrowly defined in RAAs.
>      > >
>      > >
>      > >
>      > > Farzaneh
>      > >
>      > >
>      > > On Tue, Jun 16, 2026 at 10:22 AM 鄭嘉逸 Chia I Cheng <
>      > > 00001edb87ceea84-dmarc-request at listserv.syr.edu
>     <mailto:00001edb87ceea84-dmarc-request at listserv.syr.edu>> wrote:
>      > >
>      > >>
>      > >> Hi all,
>      > >>
>      > >> I'm broadly aligned with the direction of the discussion, but
>     I think
>      > >> it's worth pausing to consider why this proposed change is
>     being raised
>      > >> within the SCCI framework specifically — that context seems
>     important to
>      > >> how we shape our response.
>      > >>
>      > >> On the substantive question: is excluding "DNS Abuse"
>     altogether actually
>      > >> to our advantage? If the term can be held to a narrow,
>     operationally
>      > >> precise definition — one explicitly grounded in user rights
>     and human
>      > >> rights principles — we may end up with more meaningful control
>     over how it
>      > >> is applied than a rejection would give us.
>      > >> Best,
>      > >>
>      > >> Chia-I
>      > >>
>      > >> *寄件者: *NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
>     <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> 代表 NPC SVG <
>      > >> 0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU
>     <mailto:0000220936dcebb1-dmarc-request at LISTSERV.SYR.EDU>>
>      > >> *日期: *星期二, 2026年6月16日 清晨6:12
>      > >> *收件者: *NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
>     DISCUSS at LISTSERV.SYR.EDU> <NCSG-DISCUSS at LISTSERV.SYR.EDU
>     <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>>
>      > >> *主旨: *Re: SCCI Criteria 4 - “domain name security threats”
>      > >>
>      > >> Like Abbas and Julf , I also believe the use of the term DNS abuse
>      > >> broadens the indicator into an area unsuitable for the GNSO
>     council for
>      > >> reasons described below.
>      > >>
>      > >> RD
>      > >>
>      > >> On Mon, Jun 15, 2026, 3:08 PM <
>      > >> 0000222a86a53d44-dmarc-request at listserv.syr.edu
>     <mailto:0000222a86a53d44-dmarc-request at listserv.syr.edu>> wrote:
>      > >>
>      > >> Julf, I agree with the analysis by Abbas. Explicitly Including
>     “DNS
>      > >> abuse” broadens the indicator into an area unsuitable for the
>     GNSO Council
>      > >> for the reasons he describes.
>      > >>
>      > >>
>      > >>
>      > >> In terms of a statement, we can perhaps relate something like
>     “the ICANN
>      > >> community has reached general consensus around a narrow set of
>     DNS security
>      > >> threats (phishing, malware, botnets, pharming, and spam as a
>     delivery
>      > >> mechanism). However, there has not been universal stakeholder
>     consensus on
>      > >> the broader conceptual definition of DNS Abuse or on where the
>     boundary
>      > >> lies between DNS abuse and content abuse. Therefore, since the
>     term DNS
>      > >> abuse” can mean different things to different stakeholders,
>     even within the
>      > >> narrow threats mentioned, by including "DNS abuse" as an
>     indicator for
>      > >> evaluating the performance of the GNSO council risks creating
>     unclear, and
>      > >> potentially unrealistic, expectations for achieving the stated
>     criteria, to
>      > >> say nothing of the opportunity for debate regarding whether or
>     not the
>      > >> criteria has been met.”
>      > >>
>      > >>
>      > >>
>      > >> I hope this helps.
>      > >>
>      > >>
>      > >>
>      > >> Ken
>      > >>
>      > >>
>      > >>
>      > >> *From:* NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU
>     <mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> *On Behalf Of *Abbas
>      > >> Sibai
>      > >> *Sent:* Monday, June 15, 2026 9:33 AM
>      > >> *To:* NCSG-DISCUSS at LISTSERV.SYR.EDU <mailto:NCSG-
>     DISCUSS at LISTSERV.SYR.EDU>
>      > >> *Subject:* Re: SCCI Criteria 4 - “domain name security threats”
>      > >>
>      > >>
>      > >>
>      > >> Hi Julf,
>      > >>
>      > >> Thanks for flagging this. As an individual member of the NCUC, I
>      > >> completely share your concerns. Specifically inserting the
>     term "DNS Abuse"
>      > >> into the GNSO Continuous Improvement Program framework is a
>     major red flag
>      > >> that we definitely need to push back against during the
>     upcoming call on
>      > >> Wednesday, 1 July 2026.
>      > >>
>      > >> From our constituency’s perspective, my understanding is that
>     there are
>      > >> two distinct "cans of worms" this proposal opens up:
>      > >>
>      > >>    - *Mission Creep and Content Regulation:* Broadening the
>     text to
>      > >>    explicitly name "DNS Abuse" risks shifting the GNSO's focus
>     from core
>      > >>    technical layer infrastructure toward content regulation.
>     What I
>      > >>    understood is that the NCUC has a long-standing commitment to
>      > >>    fiercely protecting freedom of expression and digital
>     rights. If the
>      > >>    indicators explicitly target "DNS Abuse" rather than
>     strictly defined
>      > >>    security threats, it invites outside pressure on the GNSO
>     to police website
>      > >>    content, a precedent that directly undermines our core
>     mission and
>      > >>    human rights principles.
>      > >>    - *Disproportionality and Human Rights Impacts:* I also
>     understood
>      > >>    that  NCUC has consistently advocated that any policy
>     intervention
>      > >>    addressing domain security must be narrow, proportionate,
>     and strictly
>      > >>    scoped. Tying the evaluation of the GNSO's performance to
>     broad and
>      > >>    subjective perceptions of "DNS Abuse" (especially via a
>     survey indicator)
>      > >>    creates an incentive to pass sweeping, reactive policies.
>     This places
>      > >>    innocent registrants at risk of collective or automated
>     domain suspensions
>      > >>    without adequate due process or Human Rights Impact
>     Assessments (HRIAs).
>      > >>
>      > >> The original text, focusing strictly on "mitigating domain
>     name security
>      > >> threats," keeps the evaluation grounded within the GNSO's
>     technical and
>      > >> contractual scope. The proposed revision unnecessarily
>     complicates it and
>      > >> opens the door to over-policing at the registry/registrar level.
>      > >>
>      > >> I fully support our leadership taking a strong stance against
>     this text
>      > >> on Wednesday. Please let me know if you need any assistance
>     with drafting a
>      > >> formal statement or if there are specific points you want
>     supported during
>      > >> the call.
>      > >>
>      > >>
>      > >> Warm Regards,
>      > >>
>      > >> *Abbas Sibai*
>      > >> *Policy & Advocacy Specialist*
>      > >>
>      > >> +9613824725
>      > >>
>      > >> *|*
>      > >>
>      > >> https://www.linkedin.com/in/abbas-sibai/ <https://
>     www.linkedin.com/in/abbas-sibai/>
>      > >>
>      > >>
>      > >>
>      > >>
>      > >>
>      > >> On Mon, Jun 15, 2026 at 12:28 PM Johan Helsingius <
>      > >> 00001963cc94b85a-dmarc-request at listserv.syr.edu
>     <mailto:00001963cc94b85a-dmarc-request at listserv.syr.edu>> wrote:
>      > >>
>      > >> Hi all,
>      > >>
>      > >> I am the NCSG representative to the Standing Committee on
>     Continuous
>      > >> Improvement (SCCI) that is formulating the Continuous Improvement
>      > >> Program framework. The SCCI is chaired by Manju, another
>     NCSG:er, but
>      > >> as chair she has to remain neutral.
>      > >>
>      > >> The work until now has been developing the Criteria and Indicators
>      > >> that will be used to judge how well the GNSO processes are
>     working.
>      > >>
>      > >> We have made good progress under the very capable leadership
>     of Manju,
>      > >> and most issues haven't been very controversial, but I want to
>     flag
>      > >> the current issue where we probably want to speak up against
>     the current
>      > >> proposal.
>      > >>
>      > >> The issue is Criteria 4, "The GNSO actively combats domain name
>      > >> security threats", where there is a proposal to change the draft
>      > >> text from:
>      > >>
>      > >>      Indicator 1: The GNSO has demonstrated meaningful
>     activity towards
>      > >>                   mitigating domain name security threats.
>      > >>
>      > >>      Indicator 2:  66% of surveyed respondents agree that the GNSO
>      > >>                    combats domain name security threats.
>      > >>
>      > >> to:
>      > >>
>      > >>      Indicator 1: The GNSO has demonstrated meaningful
>     activity towards
>      > >>                   mitigating DNS Abuse and security threats
>     relating to
>      > >>                   domain names that are in scope for the GNSO.
>      > >>
>      > >>
>      > >>      Indicator 2:  66% of surveyed respondents agree that the
>     GNSO has
>      > >>                    demonstrated meaningful activity towards
>     mitigating
>      > >>                    DNS Abuse and security threats relating to
>     domain
>      > >>                    names that are in scope for the GNSO.
>      > >>
>      > >> While we probably are OK with mitigating domain name security
>     threats,
>      > >> specifically mentioning DNS Abuse opens up some cans of worms.
>      > >>
>      > >> We will have a chance to present our views at the next SCCI
>     call on
>      > >> Wednesday, 1 July 2026, so I welcome your comments/opinions.
>      > >>
>      > >>         Julf
>      > >>
> 


More information about the Ncsg-discuss mailing list